CVE-2026-59921
Medium · CVSS 5.7Published 2026-07-28
CVSS
5.7
EPSS
—
Exploited
No
Summary
Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, HttpPostRequestEncoder constructs multipart HTTP request bodies by directly concatenating user-supplied filenames and field names into Content-Disposition MIME headers without validating or sanitizing CRLF characters (\r\n). Since MIME headers are delimited by CRLF, an attacker who controls the filename can inject arbitrary MIME headers into the multipart body part. The root cause is that neither the encoder nor the FileUpload implementations' setFilename() methods, which only check for null, neutralize CRLF characters before the filename is embedded into the header. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final.
References
Is your stack affected?
Pentevo's AI pentest continuously checks your systems against known vulnerabilities like this one.
Recent CVEs
- CVE-2026-65441Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.3 versions.7.1
- CVE-2026-65442Unauthenticated Server Side Request Forgery (SSRF) in FormCraft <= 3.9.15 versions.7.2
- CVE-2026-65443Unauthenticated Cross Site Scripting (XSS) in BackWPup <= 5.7.4 versions.7.1
- CVE-2026-65445Unauthenticated Broken Access Control in Ad Invalid Click Protector (AICP) <= 1.3.0 versions.6.5
- CVE-2026-65446Unauthenticated Cross Site Scripting (XSS) in Kali Forms <= 2.4.18 versions.7.1
- CVE-2026-65447Unauthenticated Cross Site Scripting (XSS) in Contest Gallery <= 30.0.6 versions.7.1